PCI DSS (Payment Card Industry Data Security Standard) is the security standard that any organisation storing, processing or transmitting cardholder data must meet. It is maintained by the card networks and enforced through acquirers and processors, with requirements covering network security, encryption of cardholder data in transit and at rest, access control, vulnerability management, logging and monitoring, and regular testing.
Definition
PCI DSS (Payment Card Industry Data Security Standard) is the security standard that any organisation storing, processing or transmitting cardholder data must meet. It is maintained by the card networks and enforced through acquirers and processors, with requirements covering network security, encryption of cardholder data in transit and at rest, access control, vulnerability management, logging and monitoring, and regular testing.
Compliance is validated annually, with the depth of validation (a self-assessment questionnaire versus a full external audit) scaling to transaction volume and how the merchant handles card data.
The practical way most merchants reduce their PCI burden is to avoid touching raw card data at all: using a hosted payment page, an iframe, or tokenisation so the card details go straight to a PCI-compliant provider and the merchant only ever handles a token. This shrinks the scope of what has to be secured and audited.
In context
For licensed iGaming operators, PCI DSS is a baseline obligation that sits alongside gambling-specific regulation. Operators almost always keep card data out of their own systems by using a PCI-compliant PSP and tokenisation, so their own scope is limited, but they remain responsible for the parts they control: the security of the pages that load the payment form, protection against injection and skimming attacks on the checkout, secure handling of any stored tokens, access controls, and vendor due diligence on every provider in the payment path.
A card-data breach would bring network penalties, acquirer action, regulatory scrutiny and serious reputational damage on top of the direct incident cost.
For affiliates, PCI DSS is not something they handle directly (they should never be collecting card data), but it is part of assessing whether an operator is a safe recommendation. A legitimate licensed operator will process cards through recognised PCI-compliant providers, show a hosted or tokenised payment flow, and run checkout over properly configured TLS.
Signs to the contrary — a site asking for full card details in a plain form on its own domain, insecure connections, or card data reused across unrelated sites — indicate poor security practice and are a reason not to promote the brand. Affiliates covering payment security for readers can accurately say that reputable operators do not store card numbers themselves and that entering card details should always happen on a secure, provider-backed page.
Worked example
An operator processes all card payments through a PCI-compliant PSP using a hosted payment page, so raw card numbers never reach its servers and its PCI scope is minimal. Its security team still monitors the checkout for script-injection and keeps vendor attestations current.
An affiliate review notes the operator uses a recognised payment provider and a secure hosted checkout as a trust signal.
Related terms
Frequently asked questions
Browse the full iGaming & affiliate glossary — hundreds of EN/RU terms with examples.
← Back to glossary